scheduler

Warn

Audited by Socket on Aug 26, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
executor.py

The code is a legitimate-looking configurable shell-job runner. It contains significant security risk if job definitions, job names, or workdirs are attacker-controlled because shell=True enables arbitrary command execution, inherited environment variables may expose secrets, and log paths are insufficiently validated in this fragment. No direct evidence of intentional malware or supply-chain sabotage is present. Use trusted, validated job definitions, avoid shell=True where possible, sanitize names, restrict environment variables, and terminate process groups on timeout.

Confidence: 97%Severity: 72%
SecurityMEDIUM
metrics_server.py

The code appears to implement a scheduler monitoring and control API, not malware. However, exposing it on 0.0.0.0 without authentication allows remote users to disclose job commands, working directories, logs, and runtime state, and to trigger arbitrary registered scheduler jobs. The log filename construction should use strict name validation and containment checks. Restrict network access or add authentication and authorization before deployment. The fragment is incomplete as provided, so full runtime behavior cannot be confirmed.

Confidence: 96%Severity: 78%
Audit Metadata
Analyzed At
Aug 26, 2026, 06:04 PM
Package URL
pkg:socket/skills-sh/grahama1970%2Fagent-skills%2Fscheduler%2F@b798352c3da4db5b0267352a8b6d0b083ac40d46
Security Audit — socket — scheduler